Re: dpkg MD5
Jeremy Stanley <[email protected]> Thu, 7 Nov 2024 23:37:41 +0000
| Newsgroups | gmane.linux.debian.devel.security |
|---|---|
| Message-ID | <[email protected]> |
On 2024-11-07 16:45:54 -0500 (-0500), David Campbell wrote: [...] > dpkg currently uses MD5 to verify packages, but MD5 is considered > insecure, why not switch to SHA256 (and also update lintian)? [...] MD5 is considered insecure to collision attacks, but mounting one would require that the creator of the original file intentionally pick content that can hash to the same value as some malicious content (and even that is nontrivial, but let's set that aside for the moment). https://en.wikipedia.org/wiki/Collision_attack What you're probably worried about is preimage resistance of the algorithm (and in particular, second preimage resistance, which is what keeps some random attacker from creating a file which hashes to the same value as a known good file). https://en.wikipedia.org/wiki/Preimage_attack MD5's preimage resistance is not in question presently, that I've heard, and it would be pretty big news in the cryptography community if it were. > Please, include my email address in the CC if you respond to this > message. I am not subscribed to the mailing list. [...] Sorry, GMail doesn't accept messages from my mailserver, and I'm not going to bother jumping through hoops just to appease them. Anyone who's interested in Debian security matters should subscribe to the mailing list or read its archives in a Web browser at the very least. -- Jeremy Stanley
signature.asc
(application/pgp-signature, 963 B)
-----BEGIN PGP SIGNATURE----- iQKTBAABCgB9FiEEl65Jb8At7J/DU7LnSPmWEUNJWCkFAmctTz5fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDk3 QUU0OTZGQzAyREVDOUZDMzUzQjJFNzQ4Rjk5NjExNDM0OTU4MjkACgkQSPmWEUNJ WCnc2A/6Ajqldxzx+5zv+5bIkdWIFJ8WtcUGgaAWwnNnm5BTdIAMJIK3/Qvrr/zD PcZcTPmiVhQS9TN2FZdveZON2XBY9smAfua6qbJJWCYK7wu/2FNpqRlTiPZHXk7Z +hMkQ54zgtSv45ZtzjsVSFCCXBsProaHEQCJewigFrwcJNfEcVtiOdH2FPStBvfT QFNs4A+iJdbIGxI4wNKzzdmSb1EzHVKkwEUlW24gAfNV+glUI0ml1XWnP15cdhc4 eYoZhyFib4LzTb+vip0BCq9tq/qaeItPP2BB9NEnF40woG9IHxGG3Uuywk8V0DPW NHQEUb794xadxpTqhRwqzarCg82op7A6Qyz2GS764luIx1dlxc6upRtGjM4iUHMb FsibHTcPHXyLkwWp0AuS9NnWUtLP8ZDN3kOIElr3a87B1WH5Q5IynmhauwifH0aD w6a7xdovI1lKEYnE1Y9o8ajDTRepD0YShEI66UG3kBHl2YxtvzzLi3vV4rGl95q3 HXuJFFN4Bvp9UeT3azxZQKBQLBJhoMRsw/zja7pS5NmBpWMiqlpJuKmDQzhQ5++s coUk/DA7CJinIVohA7AZV7wtplXOnlL8bnOA0pcc8g/gjpL7W9sadwPaMaomUFhO zP6y0Fl2f6Ey3J1qgkXWBEK+DUXNSLCNQZGexncu1hY05grvsT8= =91Dl -----END PGP SIGNATURE-----